Start with the risk itself
A project risk is something that might happen and would affect the project if it did. If the problem has already happened, it is usually an issue rather than a risk.
A useful risk description normally includes the cause, the uncertain event and the possible effect. For example: user testing has started later than planned, so critical defects may remain unresolved at launch, which could delay release or cause operational problems.
Likelihood and impact
Most project risk matrices score two things: how likely the risk is to happen and how serious the effect would be. A common approach is a 1 to 5 scale for each, with the two numbers multiplied together.
The arithmetic is simple. The judgement behind it is the important part. If your organisation already has definitions for each score or an agreed risk matrix, use those instead of inventing your own.
A score helps you compare risks and decide what needs attention. It does not remove the need to explain why the ratings were chosen.
Current risk and residual risk
Current risk is the exposure you're carrying now. Residual risk (or post-mitigation risk) is the level of risk you expect to be left with after the agreed mitigation actions have been completed and are having the intended effect.
Do not reduce a residual score just because a mitigation has been written into the register. Reduce it when there is a reasonable basis for believing the mitigation will actually change the likelihood or impact.
Mitigation, contingency and triggers
- Mitigation
- Something you do before the risk happens to reduce its likelihood or impact.
- Contingency
- The action you plan to take if the risk actually happens.
- Trigger
- The event or threshold that tells you the contingency should start.
- Risk owner
- The person accountable for keeping the risk under review and making sure the agreed response happens.
A simple worked example
Risk: a key business process may not be ready for the planned launch date because user testing has started later than expected. Current assessment: likelihood 4, impact 4, score 16. Mitigation: prioritise the critical test scenarios, add extra test sessions and review progress twice a week. Residual assessment: likelihood 2, impact 4, score 8, if testing catches up as planned. Contingency: delay the affected part of the launch and release it separately once testing is complete. Trigger: fewer than 80% of critical test scenarios have passed one week before launch.
What to include in a risk register
At a minimum, record the risk, the risk owner, the current likelihood and impact scores, the mitigation actions, the residual likelihood and impact scores, any contingency, and the next review date. The register should help you manage the risks, not become a document that is updated for its own sake.
Free Excel resource
Download the PMZ project risk register
The workbook gives you a practical risk register you can use on your own project, with current and residual scoring, mitigation and contingency fields, owners, review dates, a worked example and a simple scoring guide. No sign-up is required.
A more detailed version of the risk register is included in the First 30 Days toolkit.
Related PMZ resource
Check the wider health of your project
This is practical guidance, not a replacement for your organisation's risk policy, governance or escalation rules.